18-Question DPDP Readiness Check

The DPDP Readiness
Diagnostic.

Built with compliance experts and the teams who manage data every day, these eighteen questions are drawn from the real situations companies face under the DPDP Act, 2023 — data mapping, consent, rights, security, breach readiness, vendors, retention and governance. No judgment, no gimmicks — just honest questions about how things actually work at your company. Answer them, and the moment you submit you'll get a clear, personalised summary of where you stand and exactly what to build next.

First, a little contextTakes 30 seconds

Tell us about your company so we read your answers in the right context.

The DPDP burden is very different for a 10-person startup vs a large data business. These five answers keep your result fair and personal — nothing here is scored. No jargon needed — tap any underlined term for a plain-English explanation.

New to these terms? Plain-English glossary
Data fiduciary
The company that decides why and how personal data is used — that's you.
Data principal
The individual whose data it is — your user, customer, or employee.
Consent
Clear permission a person gives to use their data for a specific purpose — freely given, and they can withdraw it.
Processor (data processor)
A vendor that handles personal data for you (e.g. a cloud, payroll, or analytics provider).
DPA
Data Processing Agreement — a contract clause making a vendor handle personal data safely and only as instructed.
Grievance officer
A named contact people can reach to raise data complaints.
Significant Data Fiduciary
A larger or higher-risk data business the government can hold to stricter rules, like appointing a Data Protection Officer.
DPO (Data Protection Officer)
The person formally responsible for privacy compliance.
Encryption at rest
Scrambling stored data so it's unreadable if stolen.
Encryption in transit
Scrambling data while it's being sent so it can't be intercepted.
Retention
How long you keep data before deleting it.
Personal data breach
Any loss, leak, or unauthorised access to personal data.
Data Protection Board
The Indian regulator that enforces the DPDP Act.
Your company

How big is the company?

Data footprint

Roughly how many people's data do you hold?

Type of data

What kind of personal data do you collect?

Where you are

Where's your privacy program today?

Your sector

What's your industry?

0 % Readiness

Your DPDP Readiness Score

What's working

Biggest opportunity

Your next move

Readiness projection

If you closed the top three opportunities below over the next few months —

A directional view of how much of the DPDP picture you'd have covered. Indicative, not a legal opinion — real readiness depends on execution and your specific data profile.

+0%Overall readiness lift
+0%Rights & consent lift
+0%Security & breach lift
Data Inventory & Mapping 0/6

Consent & Notice 0/6
Rights & Grievance 0/9

Security Safeguards 0/9

Breach Readiness 0/6

Vendor Management 0/9

Retention & Deletion 0/6

Governance & Accountability 0/3

Where focus would pay off fastest

Take your results with you

Your responses are yours to keep. Download them free, or unlock a fuller pillar-by-pillar action report — no pressure, entirely optional.

Unlock your detailed DPDP report

Tell us where to send it. We'll build a fuller, pillar-by-pillar action report you can download right away.

Want a second pair of eyes on your DPDP roadmap?

This report is yours to act on at your own pace. If it's useful to talk it through, Muskan can read your diagnostic in advance and share an honest view on what to build first — but there's absolutely no pressure to.

Chat with Muskan